Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14350

Опубликовано: 13 авг. 2020
Источник: redhat
CVSS3: 7.1

Описание

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

A flaw was found in PostgreSQL, where some PostgreSQL extensions did not use the search_path safely in their installation script. This flaw allows an attacker with sufficient privileges to trick an administrator into executing a specially crafted script during the extension's installation or update. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

In Red Hat Gluster Storage 3, PostgreSQL was shipped as a part of Red Hat Gluster Storage Console that is no longer supported for use with Red Hat Gluster Storage 3.5. Red Hat Gluster Storage Web Administration is now the recommended monitoring tool for Red Hat Storage Gluster clusters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkuspostgresqlNot affected
Red Hat Decision Manager 7postgresqlNot affected
Red Hat Enterprise Linux 5postgresqlOut of support scope
Red Hat Enterprise Linux 5postgresql84Out of support scope
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlWill not fix
Red Hat Enterprise Linux 8libpqNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Red Hat Fuse 7postgresqlNot affected
Red Hat JBoss Enterprise Application Platform 6postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1865746postgresql: Uncontrolled search path element in CREATE EXTENSION

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

CVSS3: 7.3
nvd
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

CVSS3: 7.3
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.3
debian
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path s ...

CVSS3: 7.3
github
больше 3 лет назад

Untrusted Search Path in PostgreSQL

7.1 High

CVSS3